
GIAC Strategic Planning, Policy, and Leadership
Domain 2Objective 3
Security Program Analysis GSTRT Practice Questions (Page 3)
Part of the Policy and Program Management domain, which makes up ~45% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~32–54 in this domain), expect 8–14 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 11–15
- 11
A non-profit organization that provides legal aid to vulnerable populations has a strong value of confidentiality. The organization is considering moving its case management system to a cloud provider to reduce costs. The current security program has no cloud experience and relies on on-premises servers. The board is concerned about client confidentiality. What should the security team recommend?
Select an answer first - 12
A manufacturing company is experiencing rapid growth and plans to double its workforce and expand into new international markets. The security team is updating the security program analysis. Which factor should be prioritized when forecasting future security needs?
Select an answer first - 13
A utility company is assessing its security program. The company's core value is 'reliability and public safety.' The assessment finds that the current program is compliant with regulations but lacks proactive threat hunting. The company is facing increasing cyber threats from nation-state actors. The leadership is risk-averse and prefers incremental changes. What should the security team recommend?
Select an answer first - 14
A healthcare nonprofit's security program assessment reveals that the organization's core value of 'patient privacy above all' conflicts with a proposed security analytics tool that would collect and analyze patient data for threat detection. The board asks the security team to reconcile this tension. What should the security team do?
Select an answer first - 15
A startup's core values include radical transparency and employee autonomy. The security team is analyzing the program and finds that employees have access to almost all company data. The company is planning to raise a funding round that will require compliance with investor security requirements. What is the best way to align the security program with the company's values?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSTRT” is a trademark of its owner, used for identification only.